IP Library › Granted Patent US 12,506,815
Granted Patent B2
US 12,506,815 · App. 18/464,083 · Granted Dec 23, 2025

Managing access across a cloud boundary

Inventors: Charles Damian O'Neill (Ballymena, GB); Antoine Sibout (Barcelona, ES); Hayden Paul Shorter (Bangor, GB)
Assignee: Juniper Networks, Inc.
H04L67/61H04L41/5006H04L47/25
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,815
App. No.
18/464,083
Granted
Dec 23, 2025
Kind
B2
Abstract

This disclosure describes techniques for managing and/or regulating access, by applications executing in a cloud environment, to network resources operating outside of the cloud environment. In one example, this disclosure describes receiving, from a first application executing in a cloud environment, a first request to be delivered to an off-cloud network resource; receiving, from a second application executing in the cloud environment, a second request to be delivered to the off-cloud network resource; and managing, based on a policy, delivery of the first request and the second request to the off-cloud network resource.

Claims (49)

1 . A computing system comprising processing circuitry and a storage device, wherein the processing circuitry has access to the storage device and is configured to:

receive, from a first application executing in a cloud environment, a first request to be delivered to network resource that operates in an off-cloud environment;

receive, from a second application executing in the cloud environment, a second request to be delivered to the network resource that operates in the off-cloud environment;

generate a policy based on expected use, by the first application and the second application, of the network resource that operates in the off-cloud environment; and

manage, based on the policy and to mitigate one or more negative effects resulting from at least one of the first request and the second request, delivery of the first request and the second request to the network resource that operates in the off-cloud environment.

2 . The computing system of claim 1 , wherein to generate the policy, the processing circuitry is further configured to:

establish a service level agreement for the first application; and

establish a service level agreement for the second application.

3 . The computing system of claim 1 , wherein to generate the policy, the processing circuitry is further configured to:

generate an initial policy based on the expected use of the network resource by the first application; and

update the initial policy based on the expected use of the network resource by the second application.

4 . The computing system of claim 1 , wherein to manage delivery, the processing circuitry is further configured to:

apply one or more network management techniques to the first request and the second request.

5 . The computing system of claim 4 , wherein the policy includes:

a maximum rate at which requests are to be transmitted to the network resource.

6 . The computing system of claim 5 , wherein to apply the one or more network management techniques, the processing circuitry is further configured to:

control a rate at which requests are delivered to the network resource to ensure that the rate does not exceed the maximum rate.

7 . The computing system of claim 5 , wherein to apply the one or more network management techniques, the processing circuitry is further configured to:

queue the second request in a buffer to avoid sending requests to the network resource at a rate faster than the maximum rate.

8 . The computing system of claim 5 , wherein to apply the one or more network management techniques, the processing circuitry is further configured to:

drop requests that would cause requests sent to the network resource to exceed the maximum rate.

9 . The computing system of claim 1 , wherein the network resource is included in a plurality of network resources that operate in the off-cloud environment, and wherein the processing circuitry is further configured to:

generate a south-to-north policy for data flows from the plurality of network resources to the first application.

10 . The computing system of claim 9 , wherein to generate the south-to-north policy, the processing circuitry is further configured to:

generate the south-to-north policy based on expected data flows from each of the network resources to the first application.

11 . The computing system of claim 10 , wherein the processing circuitry is further configured to:

manage, based on the south-to-north policy, data flows to the first application.

12 . The computing system of claim 11 , wherein to manage the data flows to the first application, the processing circuitry is further configured to:

apply one or more network management techniques.

13 . The computing system of claim 12 , wherein to apply the one or more network management techniques, the processing circuitry is further configured to:

shape the data flows, queue data from the data flows, and police the data flows.

14 . The computing system of claim 11 , wherein to manage the data flows, the processing circuitry is further configured to:

scale cloud infrastructure resources of the cloud environment available to the first application.

15 . A method comprising

receiving, by a network management system and from a first application executing in a cloud environment, a first request to be delivered to a network resource that operates in an off-cloud environment;

receiving, by the network management system and from a second application executing in the cloud environment, a second request to be delivered to the network resource that operates in the off-cloud environment;

generating, by the network management system, a policy based on expected use of the network resource that operates in the off-cloud environment by the first application and the second application; and

managing, by the network management system and based on a policy, delivery of the first request and the second request to the network resource that operates in the off-cloud environment to mitigate one or more negative effects resulting from at least one of the first request and the second request.

16 . The method of claim 15 , wherein generating the policy includes:

establishing a service level agreement for the first application; and

establishing a service level agreement for the second application.

17 . The method of claim 15 , wherein generating the policy includes:

generating an initial policy based on expected use of the off cloud network resource by the first application; and

updating the initial policy based on expected use of the off cloud network resource by the second application.

18 . Non-transitory computer-readable media comprising instructions that, when executed, configure processing circuitry of a computing system to:

receive, from a first application executing in a cloud environment, a first request to be delivered to a network resource that operates in an off-cloud environment;

receive, from a second application executing in the cloud environment, a second request to be delivered to the network resource that operates in the off-cloud environment;

generate a policy based on expected use of the network resource that operates in the off-cloud environment by the first application and the second application; and

manage, based on the policy and to mitigate one or more negative effects resulting from at least one of the first request and the second request, delivery of the first request and the second request to the network resource that operates in the off-cloud environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2023
From: O'NEILL, CHARLES DAMIAN; SIBOUT, ANTOINE; SHORTER, HAYDEN PAUL
To: JUNIPER NETWORKS, INC
Reel/Frame 064850/0885 →
Continuity (1)
Related Publication 20250088572A1 · Mar 13, 2025
References Cited (12)
US 9325558B2 · Thang et al. · 2016 [cited by applicant]
US 11003502B2 · Ahmed et al. · 2021 [cited by applicant]
US 11068314B2 · Roy et al. · 2021 [cited by applicant]
US 20150358251A1 · Varga et al. · 2015 [cited by applicant]
US 20160182345A1 · Herdrich et al. · 2016 [cited by applicant]
US 20190289082A1 · Furuichi · 2019 [cited by examiner]
US 20210105338A1 · Oyman · 2021 [cited by examiner]
US 20230031741A1 · Tomar · 2023 [cited by examiner]
Extended Search Report from counterpart European Application No. 24154807.2 dated Apr. 3, 2024, 7 pp. [cited by applicant]
“AppFormix: Realize the Performance of Your Cloud Infrastructure,” Intel, 2016 (Applicant points out, in accordance with MPEP 609.04(a), that the year of publication, 2016, is sufficiently earlier than the effective U.S… [cited by applicant]
“Configure Quality of Service for Pods,”, https://kubernetes.io/docs/tasks/configure-pod-container/quality-service-pod/, Last modified Aug. 24, 2023, 8 pp. [cited by applicant]
Response to Extended Search Report dated Apr. 3, 2024, from counterpart European Application No. 24154807.2 filed Sep. 12, 2025, 25 pp. [cited by applicant]